obsidian-vault
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides bash commands like
findandgrepto interact with a local directory. These commands are limited to the path/mnt/d/Obsidian Vault/AI Research/and are used for file discovery and content searching.\n- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it reads and processes user-controlled markdown files.\n - Ingestion points: File reading via search workflows in
SKILL.md.\n - Boundary markers: Absent; no delimiters are defined to separate note content from agent instructions.\n
- Capability inventory: Uses shell commands
findandgrepto access the local file system.\n - Sanitization: Absent; no filtering or validation of note content is mentioned.
Audit Metadata